Ask HN: How to deal with a spam/automation attack on a small startup?
We run a SaaS web app that's a productivity tool used by hundreds of small to mid size businesses. While emails aren't a core part of the service, transactional emails that alert and remind users of project activity are a big part in getting users active and using the platform.
Recently, we've had malicious users sign up under domains of Chinese email providers (frequently used by spammers), and automate sending thousands of invitations to bogus emails from the same domains. While this hasn't affected our servers or performance overall, it has resulted in our AWS SES bounce rates going exorbitantly high. Our account is now on probation.
We've deleted accounts, blocked IPs, and tried adding filtering and firewalls, but we're scratching our head on a good way to eliminate the potential for this issue going forward without being a detriment to the user experience for our regular users.
Have you experienced this with your company at all? And any suggestions to help fix this? Is there any recourse to finding out who is behind this and their motives?
Would greatly appreciate your help. Thanks so much in advance.